Qilin, also known as Agenda, is a financially motivated ransomware-as-a-service operation that emerged in 2022 and later rebranded under the Qilin name. It has become one of the most active ransomware ecosystems, with a Russia-linked or Russian-speaking affiliate model and reported restrictions against targeting organizations in Russia and other CIS countries. Qilin has targeted a wide range of sectors, including healthcare, manufacturing, financial services, government, education, legal services, retail, technology, and industrial organizations, with the United States frequently identified as the most affected country.
Qilin operates through affiliates while core operators provide the encryptor, leak infrastructure, negotiation support, and payload customization features. The group is associated with double extortion, combining file encryption with theft and threatened publication of victim data. Its affiliate offering has expanded over time to include customizable payload options, large-scale data hosting, negotiation support, and coercive pressure tactics such as legal-themed extortion services. Public reporting has also linked Qilin deployments to other threat actors and access brokers, including Scattered Spider, Moonstone Sleet, and intrusion chains involving ModeloRAT.
Initial access has been associated with targeted phishing and spearphishing, theft of administrator credentials, abuse of exposed remote services such as RDP and VPNs, and exploitation of public-facing enterprise vulnerabilities including flaws in backup, VPN, and edge infrastructure. More recent reporting indicates strategic phishing campaigns aimed at managed service providers, including lures impersonating remote management authentication alerts to steal credentials, session cookies, and MFA tokens for downstream account takeover.
Post-compromise activity attributed to Qilin includes credential theft, privilege escalation, defense evasion, lateral movement, and broad ransomware deployment across enterprise environments. Reported tooling and behaviors include use of Mimikatz, PowerShell, PsExec, browser credential harvesting, deletion of logs, destruction of shadow copies and backups, termination of security processes and services, and in some cases propagation across domain environments or virtualization infrastructure. Qilin has also been associated with BYOVD-style defense suppression in some reporting on industrial intrusions. Variants have supported spreading to remote systems and VMware environments, and operators have been observed using common administrative mechanisms to scale deployment.
Technically, Qilin evolved from earlier Go-based implementations to more advanced Rust-based variants, including Qilin.B. Reported capabilities include anti-analysis checks, packed or obfuscated code, password-gated execution, configurable encryption behavior, and support for Windows, Linux, and ESXi targets. Encryption implementations described in public reporting include combinations of ChaCha20, AES-256, and asymmetric key protection. The malware is tailored per victim or affiliate configuration, with customizable ransom notes, file extensions, process kill lists, and execution parameters.
Qilin has been linked to major disruptive incidents, including attacks affecting healthcare and municipal operations, and is widely regarded as a leading ransomware threat due to its active affiliate ecosystem, adaptable tooling, and sustained operational tempo.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
it was discovered proactively by Check Point's BLAST AI platform during the investigation of CVE-2026-50751, a critical (CVSS 9.3) authentication bypass that the Qilin ransomware operation is already exploiting in the wild against Check Point Remote Access VPNs.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. CVE-2024–21762, patched in February 2025, remains a major concern with tens of thousands of exposed systems. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
On June 8th 2026, Check Point Research identified two CVEs (CVE-2026-50751, CVE-2026-50752) which can be abused to bypass Checkpoint VPN Authentication services, allowing threat actors to access network devices and traffic behind the VPN. | Check Point Research has medium confidence that the attacker is affiliated with Qilin as they use the Qilin ransomware toolkit.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
“ThrottleStop.sys is a legitimate, signed driver… The ThrottleStop vulnerability (CVE-2025-7771) comes from the way the driver handles memory access. Attackers can exploit this to gain control, ultimately leading to disabling security tools.”
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
Our Threat Hunter Team has separately observed ModeloRAT used in attacks that deployed Qilin ransomware, linking this tool to ransomware deployment.
220 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only as an example of ransomware whose hosting risks defenders should understand; the article is about bulletproof hosting infrastructure rather than Qilin itself.
Named only as an example of ransomware whose hosting infrastructure merits attention; the article does not analyze the malware itself.
Referenced as an example ransomware family in discussion of hosting risks; the article is not about Qilin itself.
Mentioned only as another ransomware family using Rust.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.